MutoPay for WooCommerce

Changelog

1.0.4

  • Removed “Powered by MutoPay” attribution from the default checkout description shown to customers. Per WordPress.org guidelines, credit links must not appear on user-facing interfaces without explicit admin opt-in. Merchants can still add any description they choose in the gateway settings.

1.0.3

  • Annotated Plugin Check warnings: the connect (OAuth) callback uses a state token rather than a nonce for CSRF, and the cron poller’s order meta query is intentionally bounded.

1.0.2

  • Security: added a one-time state parameter to the MutoPay connect (OAuth) callback to defend against CSRF, plus an explicit capability check on the callback handler.

1.0.1

  • Moved inline admin scripts into enqueued JS files for WordPress.org guideline compliance.

1.0.0

  • Initial release
  • Payment gateway with hosted checkout redirect
  • Webhook receiver with HMAC-SHA256 verification
  • WP-Cron fallback polling
  • HPOS compatibility

Plugin Website
Visit website

Author
mutopay
Version:
1.0.4
Last Updated
June 23, 2026
Requires
WordPress 6.0
Tested Up To
WordPress 7.0
Requires PHP
8.0

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.